Description
Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc12; MongoDB Server v4.2 versions prior to 4.2.9.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2010-2419 Vulnerability (CVE-2010-2419)
Oracle HTTP Server Other Vulnerability (CVE-2020-35167)
Apache Traffic Server Improper Input Validation Vulnerability (CVE-2017-5660)
WordPress Plugin Duplicator-WordPress Migration Cross-Site Scripting (1.2.32)
Squid Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-12529)